meitu-beauty
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the vendor-provided
meitu-clitool to perform image beauty enhancement and environment verification. It also executes a local Node.js script (oc-workspace.mjs) to determine workspace configurations and output paths. These actions are limited to the skill's intended image processing functionality. - [EXTERNAL_DOWNLOADS]: The skill documentation guides the user to install the
meitu-clipackage via the npm registry. As a vendor-owned resource, this is considered a standard dependency for the skill's operation. - [DATA_EXFILTRATION]: Portrait images provided by the user (as local files or via URLs) are transmitted to the Meitu API through the CLI tool for processing. This data movement is essential for the core functionality of the AI beauty service and is explicitly documented.
Audit Metadata